SUSE alert openSUSE-SU-2026:0205-1 (cheat)
| From: | maintenance@opensuse.org | |
| To: | security-announce@lists.opensuse.org | |
| Subject: | openSUSE-SU-2026:0205-1: important: Security update for cheat | |
| Date: | Mon, 15 Jun 2026 15:05:27 +0200 | |
| Message-ID: | <20260615130527.CDF96FCE7@maintenance.suse.de> | |
| Archive-link: | Article |
openSUSE Security Update: Security update for cheat ______________________________________________________________________________ Announcement ID: openSUSE-SU-2026:0205-1 Rating: important References: #1264943 #1265539 #1266184 #1267330 Cross-References: CVE-2026-1229 CVE-2026-39827 CVE-2026-39828 CVE-2026-39829 CVE-2026-39830 CVE-2026-39831 CVE-2026-39832 CVE-2026-39833 CVE-2026-39834 CVE-2026-39835 CVE-2026-41506 CVE-2026-42508 CVE-2026-44740 CVE-2026-46595 CVE-2026-46597 CVE-2026-46598 CVSS scores: CVE-2026-1229 (SUSE): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N CVE-2026-39827 (SUSE): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N CVE-2026-39828 (SUSE): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N CVE-2026-39829 (SUSE): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N CVE-2026-39830 (SUSE): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N CVE-2026-39831 (SUSE): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N CVE-2026-39832 (SUSE): 6.2 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N CVE-2026-39833 (SUSE): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N CVE-2026-39834 (SUSE): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N CVE-2026-39835 (SUSE): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N CVE-2026-41506 (SUSE): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N CVE-2026-42508 (SUSE): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N CVE-2026-44740 (SUSE): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N CVE-2026-46595 (SUSE): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N CVE-2026-46597 (SUSE): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N CVE-2026-46598 (SUSE): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N Affected Products: openSUSE Backports SLE-15-SP7 ______________________________________________________________________________ An update that fixes 16 vulnerabilities is now available. Description: This update for cheat fixes the following issues: - CVE-2026-41506: HTTP authentication credential leak (boo#1264943) Bump go-git to 5.18.0 - CVE-2026-1229: Fix incorrect value (boo#1265539) Bump circl to 1.6.3 - CVE-2026-39827,CVE-2026-39834,CVE-2026-39828,CVE-2026-39829,CVE-2026-39831, CVE-2026-42508,CVE-2026-39833,CVE-2026-39830,CVE-2026-39832,CVE-2026-46597, CVE-2026-46598,CVE-2026-46595,CVE-2026-39835: Fix multiple issues (boo#1266184) Bump crypto to 0.52.0 - CVE-2026-44740: Improper input handling (boo#1267330) Bump go-billy to 5.9.0 - Update to 5.1.0: * --update / -u flag: Pull the latest changes for all git-backed cheatpaths from the CLI. Reports per-path status (ok, skipped, error). Works with --path filtering to update specific cheatpaths. Supports SSH remotes via key file discovery and SSH agent. (#552) Documentation: * Fixed config filename references in man page (conf.yaml → conf.yml) * Added missing /etc/cheat/conf.yml config search path to man page * Fixed stale code references in CLAUDE.md, HACKING.md, and ADRs * Updated Go version requirement in INSTALLING.md - Update to 5.0.0: * Migrated from docopt to cobra (#768, #705, #632, #476) * Dynamic shell completions Breaking changes: * The static completion scripts under scripts/ have been removed. Users must regenerate completions using cheat --completion <shell>. * The CHEAT_USE_FZF environment variable is no longer supported. Bug fixes: * Fixed _init_completion: command not found error (#768) * Fixed autocompletion not working (#705) * Fixed zsh autocompletion not resolving cheatsheet names (#632) - Update to 4.7.1: * Internal cleanup and project restructuring. No user-facing behavior changes - Update to 4.7.0: * Brief list output (-b/--brief) - Update to 4.6.0: New Features: * Recursive .cheat directory discovery: cheat now walks up the directory tree to find .cheat directories, mirroring how git discovers .git directories. Place a .cheat directory at your project root and it will be available from any subdirectory. (#602) Documentation: * ADR-004: documents the design decisions for recursive .cheat discovery * Updated README and package docs to describe the new behaviour - Update to 4.5.2: Bug Fixes: * Static binaries: Build with CGO_ENABLED=0 to produce fully static binaries (#744) * Editor env vars: Respect $VISUAL and $EDITOR environment variables at runtime (#589) * .git in path: Fix cheatsheets being silently skipped when the cheatpath contains a directory ending in .git (#711) Other Changes: * Remove dead Homebrew formula bump workflow * Move ADRs from doc/adr/ to adr/ for discoverability - Update to 4.5.1: * Fix first-run experience (#721, #730, #771): Declining community cheatsheets during initial setup no longer causes errors on subsequent runs. config.New() now skips missing cheatpaths with a warning instead of a fatal error. * Fix --init output (#773): cheat --init now comments out the community cheatpath by default and includes clone instructions, so the output works as a config file without modification. * Fix stdin buffering in installer prompts: The installer's interactive prompts now read stdin without buffering, allowing cheat to be scripted (e.g., printf "y\nn\n" | cheat). * Fix frontmatter parsing on Windows: Line ending detection in cheatsheet frontmatter now inspects file content instead of checking runtime.GOOS, fixing parsing failures when files have Unix line endings on Windows. * CI modernized: Go 1.26, GitHub Actions v4/v5, Windows added to test matrix * Dependencies updated (addresses dependabot CVEs in golang.org/x/crypto, golang.org/x/net) * End-to-end integration tests added for first-run experience * Dockerfile updated to Go 1.26 - Update to 4.5.0: Bug Fixes: * Fix inverted pager detection logic (returned error string instead of path) * Fix repo.Clone ignoring destination directory parameter * Fix sheet loading using append on pre-sized slices, causing nil entries * Clean up partial files on copy failure * Trim whitespace from editor config during loading Security: * Add path traversal protection for cheatsheet names Performance: * Move regex compilation outside search loop * Replace O(n²) string concatenation with strings.Join in search Build & Testing: * Remove go:generate; embed config and usage as string literals * Parallelize release builds * Add fuzz testing infrastructure * Improve test coverage from 38.9% to 50.2% Documentation: * Fix inaccurate code examples in HACKING.md * Add missing --conf and --all options to man page * Add ADRs for path traversal, env parsing, and search parallelization * Update CONTRIBUTING.md to reflect project policy Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP7: zypper in -t patch openSUSE-2026-205=1 Package List: - openSUSE Backports SLE-15-SP7 (aarch64 i586 ppc64le s390x x86_64): cheat-5.1.0-bp157.2.6.1 References: https://www.suse.com/security/cve/CVE-2026-1229.html https://www.suse.com/security/cve/CVE-2026-39827.html https://www.suse.com/security/cve/CVE-2026-39828.html https://www.suse.com/security/cve/CVE-2026-39829.html https://www.suse.com/security/cve/CVE-2026-39830.html https://www.suse.com/security/cve/CVE-2026-39831.html https://www.suse.com/security/cve/CVE-2026-39832.html https://www.suse.com/security/cve/CVE-2026-39833.html https://www.suse.com/security/cve/CVE-2026-39834.html https://www.suse.com/security/cve/CVE-2026-39835.html https://www.suse.com/security/cve/CVE-2026-41506.html https://www.suse.com/security/cve/CVE-2026-42508.html https://www.suse.com/security/cve/CVE-2026-44740.html https://www.suse.com/security/cve/CVE-2026-46595.html https://www.suse.com/security/cve/CVE-2026-46597.html https://www.suse.com/security/cve/CVE-2026-46598.html https://bugzilla.suse.com/1264943 https://bugzilla.suse.com/1265539 https://bugzilla.suse.com/1266184 https://bugzilla.suse.com/1267330
